harness-eval
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The benchmarking purpose is mostly coherent, but the skill includes explicit instructions to circumvent `.claude/` sensitive-path permission checks using `/tmp` and Bash because the copy is 'not audited'. That concealment/evasion behavior is disproportionate to a reporting skill and materially raises risk even without obvious credential theft or malware payloads.
Confidence: 92%Severity: 82%
Audit Metadata